<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x setup using foreign anchor wlc in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583272#M240302</link>
    <description>&lt;P&gt;You mean to say this is correct setup and we can implement in our network?&lt;/P&gt;&lt;P&gt;Same vlan i am using for guest ssid as well and it is working fine.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Mar 2022 18:17:34 GMT</pubDate>
    <dc:creator>jain.manish94</dc:creator>
    <dc:date>2022-03-31T18:17:34Z</dc:date>
    <item>
      <title>802.1x setup using foreign anchor wlc</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583217#M240299</link>
      <description>&lt;P&gt;&lt;STRONG&gt;hello team,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Today i was trying to setup one SSID with 802.1x involvement of foreign and anchor wlc same like guest CWA.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I don't know this is possible or not but after testing user is getting authentic successfully by ISE policy but not getting ip address. It is in DHCP_Req stage.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;As per my understanding it should be working but don't know why it is not working.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Plz suggest me this is correct setup or where i doing wrong.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 17:17:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583217#M240299</guid>
      <dc:creator>jain.manish94</dc:creator>
      <dc:date>2022-03-31T17:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x setup using foreign anchor wlc</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583229#M240300</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are getting past layer 2 and the client is in DHCP required state, I would recommend the following&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Ensure the configuration on the anchor WLC has the correct interface/vlan configured and properly mapped to that SSID as this will be the WLC handling layer 3 for the clients. The foreign can have any bogus vlan&lt;/P&gt;&lt;P&gt;- Check on switch side to make sure the necessary vlans are allowed on the controller trunk link and any DHCP relay is specified as needed&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 17:30:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583229#M240300</guid>
      <dc:creator>Prince.O</dc:creator>
      <dc:date>2022-03-31T17:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x setup using foreign anchor wlc</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583272#M240302</link>
      <description>&lt;P&gt;You mean to say this is correct setup and we can implement in our network?&lt;/P&gt;&lt;P&gt;Same vlan i am using for guest ssid as well and it is working fine.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 18:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583272#M240302</guid>
      <dc:creator>jain.manish94</dc:creator>
      <dc:date>2022-03-31T18:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x setup using foreign anchor wlc</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583303#M240303</link>
      <description>&lt;P&gt;&amp;nbsp;Where does your DHCP server reside?&amp;nbsp; Keep in mind that the Anchor WLC will drop the DHCP request and for 802.1x first client autentication then it gets an ip address.&lt;/P&gt;&lt;P&gt;Make sure the wlc can get to the DHCP server properly.&amp;nbsp; As this wlc reside in a DMZ, at least should, you may need to play with firewall somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 19:00:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583303#M240303</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-03-31T19:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x setup using foreign anchor wlc</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583325#M240307</link>
      <description>&lt;P&gt;In theory, this can work but I've typically seen 802.1x SSIDs usually handled locally on one controller and guest would be guest anchor configuration network segmentation purposes. This all depends on your environment and the use case. If foreign/anchor is needed for your environment for 802.1x SSID, this is fine.&lt;/P&gt;&lt;P&gt;- You'll need to of course verify on the SSID configuration that the anchor has itself set as the anchor and the foreign has the anchor set to forward the traffic&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would not recommend having guest and 802.1x SSID in the same vlan , however, it's best to separate the two&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 19:35:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583325#M240307</guid>
      <dc:creator>Prince.O</dc:creator>
      <dc:date>2022-03-31T19:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x setup using foreign anchor wlc</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583547#M240321</link>
      <description>&lt;P&gt;Yes not using same vlan but i am doing this test in my lab where guest LWA is working fine with same vlan but not 802.1x&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 04:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583547#M240321</guid>
      <dc:creator>jain.manish94</dc:creator>
      <dc:date>2022-04-01T04:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x setup using foreign anchor wlc</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583551#M240322</link>
      <description>&lt;P&gt;&lt;STRONG&gt;yes authentication is successful because user is in DHCP_req stage&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;And this is my lab and here guest lwa is working fine with same vlan but not 802.1x so i think no need to check firewall right ?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 04:33:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583551#M240322</guid>
      <dc:creator>jain.manish94</dc:creator>
      <dc:date>2022-04-01T04:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x setup using foreign anchor wlc</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583911#M240339</link>
      <description>&lt;P&gt;Then i would recommend checking on the radius server to validate they are not pushing a vlan override for a different vlan&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 14:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-setup-using-foreign-anchor-wlc/m-p/4583911#M240339</guid>
      <dc:creator>Prince.O</dc:creator>
      <dc:date>2022-04-01T14:35:29Z</dc:date>
    </item>
  </channel>
</rss>

